
Real job — pulled straight from Planet-nine’s careers page · Verified September 20, 2026 · No reposts.
Job description
Planet-nine is hiring a Penetration Tester & Security Researcher — a full-time, based in Singapore role. Apply directly on Planet-nine's careers page below.
Penetration Tester & Security Researcher
Location: Singapore (SG)
Experience Level: Intermediate
Description
We are looking for a Mid-to-Senior Penetration Tester & Security Researcher to join our team in Singapore.
At BNF SG, we work on complex security challenges where going beyond standard testing methodologies is essential. Our engagements are typically grey-box or white-box, often with access to source code, and we expect our researchers to dig deep and uncover vulnerabilities others may miss.
Our work spans web applications, infrastructure and networks, cloud and Kubernetes environments, AI systems, mobile applications, and source code. For us, penetration testing is not just about running tools — it’s about understanding how systems work, challenging assumptions, and conducting real security research.
You’ll report to the Team Lead and work alongside a small team of security researchers in an international, collaborative, and highly technical environment. You’ll work independently on complex problems and together with the team on live client engagements.
We’re looking for someone curious and hungry to learn — someone who goes deep without being told to, would rather understand the system than simply run the tool, and genuinely enjoys security research.
Responsibilites
- Conduct penetration testing and security research across web applications, infrastructure and networks, cloud and Kubernetes environments, AI systems, mobile applications, and source code.
- Take ownership of security reporting. We use AI tools to accelerate drafting, but you are accountable for the final output — including technical accuracy, root-cause analysis, and real-world business impact.
- Present vulnerabilities, findings, and recommendations clearly to clients and their technical teams.
- Build internal security tools, methodologies, automation, and agentic workflows that enable the team to work faster and go deeper.
- Contribute to red team and adversary emulation engagements.
- Independently investigate unfamiliar technologies, attack surfaces, and complex technical problems.
Requirements
Must Have
- 3+ years of hands-on experience in penetration testing and/or security research (mandatory).
- Deep expertise in at least two of the following areas:
- Web application penetration testing.
- Infrastructure and network penetration testing, including Active Directory, with real fluency in Windows and Linux internals, the protocols underneath, and privilege escalation.
- Manual source code review and vulnerability research.
- OSCP or CREST CRT certification (mandatory).
- Strong research mindset, technical curiosity, and the ability to independently investigate unfamiliar technologies and attack surfaces.
- Hands-on experience using AI tools to support security testing, research, automation, or tool development, with a strong interest in exploring new AI-driven security workflows.
- Ability to work independently on deep technical problems and collaboratively on live client engagements.
- Excellent written and verbal English communication skills.
- Currently based in Singapore with valid work authorization (mandatory).
- Availability to work in a hybrid model in Singapore, including regular work at client sites.
Nice to Have
- Existing CAT1 or CAT2A security clearance.
- Proficiency in Python or Node.js.
- CREST CCT APP or CCT INF, or Offensive Security certifications beyond OSCP, such as OSWE, OSEP, or OSED.
- Security research publications, strong CTF performance, or a demonstrated bug bounty track record.
- Experience with mobile application penetration testing across Android and iOS, as well as thick-client testing.
- Cloud penetration testing experience across AWS, Azure, or GCP, including containers and Kubernetes.
- Red team experience, including reconnaissance, adversary emulation, and stealth techniques.
- AI security expertise, including prompt injection and indirect prompt injection, jailbreaks, RAG and agent security, and the OWASP Top 10 for LLM Applications.
- Degree in Computer Science, Information Security, Engineering, or a related discipline — or equivalent practical experience.
Get Penetration Tester jobs like this→
New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.
Email me new jobsSimilar jobs




Frequently asked questions
What skills are required for Penetration Tester & Security Researcher at Planet-nine?
The required skills for Penetration Tester & Security Researcher at Planet-nine include: Active Directory, Python, Node.js, AWS, Azure, GCP, Kubernetes, Android, iOS.
What is the seniority level for Penetration Tester & Security Researcher at Planet-nine?
Penetration Tester & Security Researcher at Planet-nine is a Mid Level / Senior level position.
How do I apply for Penetration Tester & Security Researcher at Planet-nine?
You can view the full description and apply for Penetration Tester & Security Researcher at Planet-nine on EchoJobs: https://echojobs.io/job/planet-nine-penetration-tester-security-researcher-k550d.